Ailance Alt TM Logo
Ailance Alt TM Logo

Data protection and data security with Google Drive

Data protection at Google

Google Drive and GDPR

Google Drive is one of the best-known file hosting services. Google Drive enables its users to save documents in the CloudGoogle Drive allows users to share files and edit documents together. Google Drive includes Google Docs, Sheets, Slides and Forms, an office software package that enables the shared editing of documents, spreadsheets, presentations etc. Files shared publicly on Google Drive can be found using Internet search engines. So far, so good. But how does Google Drive deal with the Data protection? What do companies need to consider if they want to use the service?

 

Data protection requirements for cloud service providers from third countries

 

One of the most important innovations of the General Data Protection Regulation is the establishment of the so-called marketplace principle. If a company, regardless of where in the world it is based, offers products or services to citizens of the European Union, it must comply with the requirements of the GDPR maintain. Conversely, European companies are required to export data to a Cloud-To ensure that providers comply with data protection laws.

Within the EU, data processing agreements are concluded for this purpose in accordance with Art. 28 GDPR closed. Become personal data outsourced to a service provider based in a third country—where access for occasional „troubleshooting“ is sufficient—the following must generally Standard contractual clauses and additional, complementary measures are taken to ensure an adequate level of data protection in the third country.

Supplementary measures can be included in a Encryption or one Anonymization of the data to be exported. The Confidentiality the data must be protected against access by government agencies or intelligence services, which is entirely legal in the United States. In the case of Encryption It is important to note that the key remains in the client's possession—in this case, not with Google.

 

What is Google offering its customers in the wake of „Schrems II“?

 

The answer to this question has to be rather flippant: Google offers quite a lot, but unfortunately hardly anything useful. For example, there is no information according to Art. 13 GDPR for the Google Drive product, but for all Google services: "This privacy policy applies to all services offered by Google LLC and its affiliates, including YouTubeAndroid and services provided on third-party websites, such as advertising services." It could hardly be more confusing and, in the opinion of the author of these lines, violates the transparency obligations of the GDPR. Even the numerous videos on data protection do not change this. Clear and simple language would be much more helpful.

With regard to the transfer of data to the USA, Google is working with the new Standard contractual clauses and offers a pre-filled sample of Module 2 EU controller-to-processor. However, the Transparency data protection and Google Drive also fall by the wayside here if, for example, Annex I of the Standard contractual clauses The data categories are described as follows: „Family, lifestyle, and social circumstances, including any information relating to the data subject’s family and the data subject’s lifestyle and social circumstances, such as details of family and other household members, habits, housing, travel details, leisure activities, and membership in charitable or volunteer organizations.“ Similar all-encompassing descriptions also exist for „Personal details,“ „Employment details,“ „Financial details,“ „Education and training details,“ and so on. Here, too, the same applies: this isn’t really transparent.

 

Transfer Impact Assessment

 

With the new Standard contractual clauses There is now a requirement to conduct a „Transfer Impact Assessment,“ a comprehensive, case-by-case Data Protection Impact Assessment before a third country transfer. The following control question must be answered: Can and will Google fulfill its contractual obligations under the GDPR actually comply? To answer this question, you would have to click through the numerous documents, annexes, videos and other links that Google has provided here. It remains to be seen whether all the information for a reliable statement can be found in the end.

And now?

As a highly standardized „Internet giant,“ Google is unlikely to address the need for clarification on the part of small and medium-sized businesses, not even with regard to Google Drive and the General Data Protection Regulation. The completion of the offered Standard contractual clauses will be based on the „take it or leave it“ principle. Companies should therefore proactively implement additional security measures and, if they choose to use Google Drive, upload only strongly encrypted data and never disclose the encryption key.

This would be one way to ensure at least some level of data protection on Google Drive in Germany. After all, it will be some time before homomorphic encryption is widely adopted Encryption It will take a little while longer. 2B Advice would be happy to assist your company with a data protection assessment of your use of Google Drive, particularly with conducting the Transfer Impact Assessment.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Data protection and data security with Google Drive